CWE-776 · 85 kayıt
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Bu sınıftaki CVE’ler
85 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2009-1955Kavram kanıtı | The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modapache · apr-util · CWE-776 | Yüksek7,5 | — | %53,0 | 7 Haz 2009 |
40Planlayın | CVE-2014-2228İstismar yok | The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML mtalend · restlet · CWE-776 | Kritik9,8 | — | %3,3 | 19 Şub 2020 |
40Planlayın | CVE-2013-4335İstismar yok | opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilitiesopenpne · opopensocialplugin · CWE-776 | Kritik9,8 | — | %2,5 | 7 Şub 2020 |
39İzleyin | CVE-2019-19144İstismar yok | XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.CWE-776 | Kritik9,8 | — | %0,7 | 1 Ağu 2025 |
38İzleyin | CVE-2017-18640İstismar yok | The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.snakeyaml project · snakeyaml · CWE-776 | Yüksek7,5 | — | %26,7 | 11 Ara 2019 |
38İzleyin | CVE-2021-23926İstismar yok | XMLBeans XML Entity Expansionapache · xmlbeans · CWE-776 | Kritik9,1 | — | %6,2 | 14 Oca 2021 |
36İzleyin | CVE-2020-24590İstismar yok | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.wso2 · api manager · CWE-776 | Kritik9,1 | — | %1,3 | 21 Ağu 2020 |
34İzleyin | CVE-2026-45304İstismar yok | Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")sensiolabs · symfony · CWE-776 | Yüksek8,7 | — | %0,7 | 14 Tem 2026 |
34İzleyin | CVE-2026-78681İstismar yok | NLTK before 3.10.3 Entity Expansion DoS via ElementTreenltk · nltk · CWE-776 | Yüksek8,7 | — | %0,5 | 24 Ağu 2026 |
34İzleyin | CVE-2026-73569İstismar yok | fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limitsnaturalintelligence · fast-xml-parser · CWE-776 | Yüksek8,7 | — | %0,5 | 13 Ağu 2026 |
34İzleyin | CVE-2026-3415İstismar yok | XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Servicewso2 · wso2 api manager · CWE-776 | Yüksek8,7 | — | %0,5 | 6 Ağu 2026 |
33İzleyin | CVE-2019-12401Kavram kanıtı | Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a.apache · solr · CWE-776 | Yüksek7,5 | — | %8,5 | 10 Eyl 2019 |
32İzleyin | CVE-2022-0217İstismar yok | It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsprosody · prosody · CWE-776 | Yüksek7,5 | — | %5,4 | 26 Ağu 2022 |
32İzleyin | CVE-2024-28982İstismar yok | Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Referencehitachi · pentaho business analytics server · CWE-776 | Yüksek8,2 | — | %0,4 | 26 Haz 2024 |
31İzleyin | CVE-2019-5427Kavram kanıtı | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursimchange · c3p0 · CWE-776 | Yüksek7,5 | — | %4,9 | 22 Nis 2019 |
31İzleyin | CVE-2011-1755İstismar yok | jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of servicjabberd2 · jabberd2 · CWE-776 | Yüksek7,5 | — | %3,7 | 20 Haz 2011 |
31İzleyin | CVE-2022-25857İstismar yok | Denial of Service (DoS)snakeyaml project · snakeyaml · CWE-776 | Yüksek7,5 | — | %2,7 | 30 Ağu 2022 |
31İzleyin | CVE-2015-9541İstismar yok | Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a relatqt · qt · CWE-776 | Yüksek7,5 | — | %2,5 | 24 Oca 2020 |
31İzleyin | CVE-2019-20104İstismar yok | The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perforatlassian · crowd · CWE-776 | Yüksek7,5 | — | %2,4 | 5 Şub 2020 |
31İzleyin | CVE-2020-5227İstismar yok | Feedgen Vulnerable to XML Denial of Service Attacksfeedgen project · feedgen · CWE-776 | Yüksek7,5 | — | %2,2 | 28 Oca 2020 |
31İzleyin | CVE-2012-6685İstismar yok | Nokogiri before 1.5.4 is vulnerable to XXE attacksnokogiri · nokogiri · CWE-776 | Yüksek7,5 | — | %2,2 | 19 Şub 2020 |
31İzleyin | CVE-2024-28757Kavram kanıtı | libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityPlibexpat project · libexpat · CWE-776 | Yüksek7,5 | — | %2,0 | 10 Mar 2024 |
31İzleyin | CVE-2022-26662İstismar yok | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.xtryton · proteus · CWE-776 | Yüksek7,5 | — | %2,0 | 10 Mar 2022 |
31İzleyin | CVE-2011-3288İstismar yok | Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote attackers to cause a decisco · unified presence · CWE-776 | Yüksek7,5 | — | %1,8 | 6 Eki 2011 |
31İzleyin | CVE-2022-33977İstismar yok | untangle is a python library to convert XML data to python objects.untangle project · untangle · CWE-776 | Yüksek7,5 | — | %1,8 | 26 Tem 2022 |
- CVE-2009-195546Planlayın
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn mod
YüksekCVSS 7,5Kavram kanıtıEPSS %53apache · apr-util7 Haz 2009
- CVE-2014-222840Planlayın
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML m
KritikCVSS 9,8İstismar yokEPSS %3talend · restlet19 Şub 2020
- CVE-2013-433540Planlayın
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %2openpne · opopensocialplugin7 Şub 2020
- CVE-2019-1914439İzleyin
XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.
KritikCVSS 9,8İstismar yokEPSS %11 Ağu 2025
- CVE-2017-1864038İzleyin
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
YüksekCVSS 7,5İstismar yokEPSS %27snakeyaml project · snakeyaml11 Ara 2019
- CVE-2021-2392638İzleyin
XMLBeans XML Entity Expansion
KritikCVSS 9,1İstismar yokEPSS %6apache · xmlbeans14 Oca 2021
- CVE-2020-2459036İzleyin
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
KritikCVSS 9,1İstismar yokEPSS %1wso2 · api manager21 Ağu 2020
- CVE-2026-4530434İzleyin
Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
YüksekCVSS 8,7İstismar yokEPSS %1sensiolabs · symfony14 Tem 2026
- CVE-2026-7868134İzleyin
NLTK before 3.10.3 Entity Expansion DoS via ElementTree
YüksekCVSS 8,7İstismar yokEPSS %1nltk · nltk24 Ağu 2026
- CVE-2026-7356934İzleyin
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
YüksekCVSS 8,7İstismar yokEPSS %1naturalintelligence · fast-xml-parser13 Ağu 2026
- CVE-2026-341534İzleyin
XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
YüksekCVSS 8,7İstismar yokEPSS %0wso2 · wso2 api manager6 Ağu 2026
- CVE-2019-1240133İzleyin
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a.
YüksekCVSS 7,5Kavram kanıtıEPSS %9apache · solr10 Eyl 2019
- CVE-2022-021732İzleyin
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in pars
YüksekCVSS 7,5İstismar yokEPSS %5prosody · prosody26 Ağu 2022
- CVE-2024-2898232İzleyin
Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference
YüksekCVSS 8,2İstismar yokEPSS %0hitachi · pentaho business analytics server26 Haz 2024
- CVE-2019-542731İzleyin
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursi
YüksekCVSS 7,5Kavram kanıtıEPSS %5mchange · c3p022 Nis 2019
- CVE-2011-175531İzleyin
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of servic
YüksekCVSS 7,5İstismar yokEPSS %4jabberd2 · jabberd220 Haz 2011
- CVE-2022-2585731İzleyin
Denial of Service (DoS)
YüksekCVSS 7,5İstismar yokEPSS %3snakeyaml project · snakeyaml30 Ağu 2022
- CVE-2015-954131İzleyin
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a relat
YüksekCVSS 7,5İstismar yokEPSS %2qt · qt24 Oca 2020
- CVE-2019-2010431İzleyin
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perfor
YüksekCVSS 7,5İstismar yokEPSS %2atlassian · crowd5 Şub 2020
- CVE-2020-522731İzleyin
Feedgen Vulnerable to XML Denial of Service Attacks
YüksekCVSS 7,5İstismar yokEPSS %2feedgen project · feedgen28 Oca 2020
- CVE-2012-668531İzleyin
Nokogiri before 1.5.4 is vulnerable to XXE attacks
YüksekCVSS 7,5İstismar yokEPSS %2nokogiri · nokogiri19 Şub 2020
- CVE-2024-2875731İzleyin
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityP
YüksekCVSS 7,5Kavram kanıtıEPSS %2libexpat project · libexpat10 Mar 2024
- CVE-2022-2666231İzleyin
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x
YüksekCVSS 7,5İstismar yokEPSS %2tryton · proteus10 Mar 2022
- CVE-2011-328831İzleyin
Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote attackers to cause a de
YüksekCVSS 7,5İstismar yokEPSS %2cisco · unified presence6 Eki 2011
- CVE-2022-3397731İzleyin
untangle is a python library to convert XML data to python objects.
YüksekCVSS 7,5İstismar yokEPSS %2untangle project · untangle26 Tem 2022